MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b5a60e20229be34f5e3e15dfa28b8fb71e48bb7dc8e09018a8376bbd90856a4a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: b5a60e20229be34f5e3e15dfa28b8fb71e48bb7dc8e09018a8376bbd90856a4a
SHA3-384 hash: 373701b88f7e644b8b4596b8437e9ca482559cbc46621ed00be75e2f292e4b791a918607237587ac709affa506e96147
SHA1 hash: bc5ac7e4afffa684e39ca9efb0c81c4fa7fed354
MD5 hash: 7da9fc48f52397ed0a566d4b6f0b1295
humanhash: cola-robin-december-london
File name:sh4
Download: download sample
Signature Mirai
File size:59'180 bytes
First seen:2025-11-01 10:30:42 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 1536:CRal65hs4s6VcWmikSX1b14eKUbwxQSPIDnK2U2nlFRgcUclVLuBTLOCUYH:CRcih1chs1b14eKUbwxQSPIDK2VFRgce
TLSH T1F0439D63D169AA94D4848578B430CBB01723B44082B72FFB5AA6C6B5B08BEFCF1553F5
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
124
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Verdict:
Malicious
File Type:
elf.32.le
First seen:
2025-11-01T07:36:00Z UTC
Last seen:
2025-11-01T12:20:00Z UTC
Hits:
~10
Detections:
HEUR:Backdoor.Linux.Mirai.b
Status:
terminated
Behavior Graph:
%3 guuid=aebd69ae-1a00-0000-13d5-48a7d10b0000 pid=3025 /usr/bin/sudo guuid=538d3cb0-1a00-0000-13d5-48a7d80b0000 pid=3032 /tmp/sample.bin guuid=aebd69ae-1a00-0000-13d5-48a7d10b0000 pid=3025->guuid=538d3cb0-1a00-0000-13d5-48a7d80b0000 pid=3032 execve
Result
Threat name:
Detection:
malicious
Classification:
troj
Score:
64 / 100
Signature
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Yara detected Mirai
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1806261 Sample: sh4.elf Startdate: 01/11/2025 Architecture: LINUX Score: 64 14 flibberwock.cfd 185.14.92.55, 23, 51408, 51410 INTERCOLO-ASintercoloIP-BackboneDE Germany 2->14 16 Antivirus / Scanner detection for submitted sample 2->16 18 Multi AV Scanner detection for submitted file 2->18 20 Yara detected Mirai 2->20 8 sh4.elf 2->8         started        signatures3 process4 process5 10 sh4.elf 8->10         started        process6 12 sh4.elf 10->12         started       
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-11-01 10:19:00 UTC
File Type:
ELF32 Little (Exe)
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai linux
Malware Config
C2 Extraction:
gqvyzb.jy.hbqwlm
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf b5a60e20229be34f5e3e15dfa28b8fb71e48bb7dc8e09018a8376bbd90856a4a

(this sample)

  
Delivery method
Distributed via web download

Comments